Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises substantial file read/write and execution-oriented behavior, but does not declare corresponding permissions or safety boundaries. This creates a capability transparency problem: users and reviewers may not realize the skill can modify workspace files, initialize agent directories, or persist state, increasing the chance of unsafe invocation.
